
MassDriver
Proxies sensitive API calls from shellcode to artifacts for CET-compatible clean call stacks, enabling stealthy payload execution and call stack…

Proxies sensitive API calls from shellcode to artifacts for CET-compatible clean call stacks, enabling stealthy payload execution and call stack…

List of mixed boolean-arithmetic resources

Obfuscates x86-64 assembly with instruction injection, junk code, constant obfuscation, and runtime decryption to hinder reverse engineering and…

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

IDA python script for deobfuscating Astaroth/Guildma injector DLL

ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Create Anti-Copy DRM Malware

DLL sideloading/proxying with Nim!

Proof-of-concept exploit for a Java gadget chain in the Mojarra library, demonstrating deserialization vulnerability exploitation for versions 2.3…


Some Rust program I wrote while learning Malware Development

Collection of different ways to execute code outside of the expected entry points

CVE 2025 27237 Zabbix LPE proof of concept.

A bin2bin code virtualizer for x86-64 PE's

An x86-64 code virtualizer for VM based obfuscation

Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.